Certified CMMC Assessor (CCA) Training
A CMMC Certified Assessor (CCA) is the certification required to perform formal CMMC Level 2 assessments within the US Department of War’s (DoW) cybersecurity ecosystem. A CCA equips experienced cybersecurity professionals with the advanced skills needed to evaluate evidence, validate security controls, conduct interviews, and determine whether organizations handling Controlled Unclassified Information (CUI) meet CMMC Level 2 requirements.
CMMC Certified Assessor (CCA)
Course Overview
In this course, you will apply the CMMC Assessment Process to validate the performance of cybersecurity practices in the 14 domains derived from NIST SP 800-171.
You will:
- Protect CUI with the CMMC program
- Establish the key elements of your responsibilities as a professional CMMC Assessor
- Work through an Assessment
- Validate the context and scope of a Level 2 CMMC Assessment
- Assess the practices in the Access Control (AC) domain
- Assess the practices in the Awareness and Training (AT) domain
- Assess the practices in the Audit and Accountability (AU) domain
- Assess the practices in the Security Assessment (CA) domain
- Assess the practices in the Configuration Management (CM) domain
- Assess the practices in the Identification and Authentication (IA) domain
- Assess the practices in the Incident Response (IR) domain
- Assess the practices in the Maintenance (MA) domain
- Assess the practices in the Media Protection (MP) domain
- Assess the practices in the Personnel Security (PS) domain
- Assess the practices in the Physical Protection (PE) domain
- Assess the practices in the Risk Assessment (RA) domain
- Assess the practices in the System and Communications Protection (SC) domain
- Assess the practices in the System and Information Integrity (SI) domain
Course Outline
- Lesson 1: Protecting CUI with the CMMC Program
- Topic A: Protect Controlled Unclassified Information
- Topic B: Utilize the CMMC Source Documents
- Lesson 2: Being an Assessor
- Topic A: Identify Assessment Roles and Responsibilities
- Topic B: Establish an Assessor Mindset
- Topic C: Determine the OSC’s Cybersecurity Environment
- Lesson 3: Working Through an Assessment
- Topic A: Identify Assessment Flow and Milestone Events
- Topic B: Prepare to Work with the OSC
- Topic C: Formalize the Plan
- Topic D: Assess the Evidence
- Topic E: Handle Non-Conformity Issues
- Topic F: Finalize the Assessment
- Lesson 4: Validating the Scope of a CMMC Assessment
- Topic A: Define Scope Fundamentals
- Topic B: Categorize the Assets
- Topic C: Determine the OSC Context
- Topic D: Define ESPs
- Topic E: Validate the Assessment Scope
- Lesson 5: Assessing the AC Practices
- Topic A: Evaluate the AC Practices
- Topic B: Identify AC Connections and Considerations
- Lesson 6: Assessing the AT Practices
- Topic A: Evaluate the AT Practices
- Topic B: Identify AT Connections and Considerations
- Lesson 7: Assessing the AU Practices
- Topic A: Evaluate the AU Practices
- Topic B: Identify AU Connections and Considerations
- Lesson 8: Assessing the CA Practices
- Topic A: Evaluate the CA Practices
- Topic B: Identify CA Connections and Considerations
- Lesson 9: Assessing the CM Practices
- Topic A: Evaluate the CM Practices
- Topic B: Identify CM Connections and Considerations
- Lesson 10: Assessing the IA Practices
- Topic A: Evaluate the IA Practices
- Topic B: Identify IA Connections and Considerations
- Lesson 11: Assessing the IR Practices
- Topic A: Evaluate the IR Practices
- Topic B: Identify IR Connections and Considerations
- Lesson 12: Assessing the MA Practices
- Topic A: Evaluate the MA Practices
- Topic B: Identify MA Connections and Considerations
- Lesson 13: Assessing the MP Practices
- Topic A: Evaluate the MP Practices
- Topic B: Identify MP Connections and Considerations
- Lesson 14: Assessing the PE Practices
- Topic A: Evaluate the PE Practices
- Topic B: Identify PE Connections and Considerations
- Lesson 15: Assessing the PS Practices
- Topic A: Evaluate the PS Practices
- Topic B: Identify PS Connections and Considerations
- Lesson 16: Assessing the RA Practices
- Topic A: Evaluate the RA Practices
- Topic B: Identify RA Connections and Considerations
- Lesson 17: Assessing the SC Practices
- Topic A: Evaluate the SC Practices
- Topic B: Identify SC Connections and Considerations
- Lesson 18: Assessing the SI Practices
- Topic A: Evaluate the SI Practices
- Topic B: Identify SI Connections and Considerations
Intended Audience
This course is designed for CMMC Certified Professionals (CCP) who are interested in becoming CMMC Certified Assessors (CCA), as well as CMMC Certified Instructors (CCI) who want to teach this CCA course in the future.
This course is also beneficial to employees of Defense Industrial Base (DIB) Organizations Seeking Certification (OSCs) because an understanding of how CCPs and CCAs think during an Assessment will ensure better Assessment readiness.
Prerequisites
To ensure your success in this course, you must have the foundational cybersecurity knowledge of a Certified CMMC Professional, which you can obtain by taking the following course and exam:
CMMC Certified Professional ( CCP )
Follow-On Courses
Related training topics
Justify your training
Use this sample request letter — copy it into an email to your manager and personalize the bracketed details to make the case for the time and budget.
Sample training request letter
Subject: Request for Governance, Risk & Compliance training from Applied Technology Academy
[Decision Maker Name],
I'm writing to request time and budget approval to complete Applied Technology Academy's course, Certified CMMC Assessor (CCA) Training. The information below outlines how this training benefits our organization, the tasks I'll be able to perform after completing it, and relevant cost and funding details.
Course Description
A CMMC Certified Assessor (CCA) is the certification required to perform formal CMMC Level 2 assessments within the US Department of War’s (DoW) cybersecurity ecosystem. A CCA equips experienced cybersecurity professionals with the advanced skills needed to evaluate evidence, validate security controls, conduct interviews, and determine whether organizations handling Controlled Unclassified Information (CUI) meet CMMC Level 2 requirements. Applied Technology Academy is an award-winning, SBA-certified woman-owned training provider (est. 2008) whose instructors are active practitioners; the course is hands-on with virtual labs and a learn-by-doing methodology.
Course Objectives
Once I've completed the course, I'll have hands-on, job-ready skills in governance, risk & compliance that I can apply immediately to our work.
Expected Organizational Benefits
After completing this course, I will be better equipped to apply these skills directly to our projects, reduce our reliance on outside expertise, strengthen our team's capabilities, and share what I learn with colleagues.
Expected Cost & Funding
Course fee: [request an itemized quote at the link below]. Applied Technology Academy supports multiple funding paths that may reduce or cover this cost: GSA MAS purchasing and government purchase orders, military credentialing funding (Army CA, AF COOL, CG COOL), VA GI Bill and VR&E, ATA Flexible Spending, and student financing. Private team cohorts are available if colleagues should attend with me.
Conclusion
This training provides practical, hands-on experience I can apply immediately to strengthen our work in governance, risk & compliance. Additional course information is available at https://appliedtechnologyacademy.com/isaca-training/cmmc-certified-assessor-cca/.
Thank you for your consideration,
[Your Name]
Related Governance, Risk & Compliance courses
Design training around your team, not the other way around.
Talk to a training advisor about private cohorts, funding paths and program management.